Effective Date: 1st July 2025
At JobsForNationals.com, safeguarding the confidentiality, integrity, and availability of our platform and user data is one of our highest priorities.
We employ a defence-in-depth security strategy, combining secure infrastructure, application security, access controls, continuous monitoring, data protection practices, and internationally recognised security principles to help protect the personal information entrusted to us.
This document provides an overview of our security commitment and the measures we implement to support the protection of our platform, users, employers, institutions, and partners.
Infrastructure Security
JobsForNationals operates on professionally managed cloud infrastructure designed to provide high availability, resilience, and security.
Our infrastructure is maintained using multiple layers of security controls that help protect systems, applications, and data against unauthorized access, service disruption, and operational risks.
Our infrastructure security practices include:
- Secure private cloud-hosted server environments
- Infrastructure isolation and resource segregation
- Automated system updates and security patching
- Regular encrypted backups and disaster recovery procedures
- Controlled administrative access using least-privilege principles
- Continuous monitoring of infrastructure health and availability
Infrastructure configurations are reviewed regularly as part of our ongoing operational and security management processes.
Network Security
We implement multiple network security controls designed to protect the platform against external threats and malicious activity.
These controls help safeguard our services against:
- Unauthorized access attempts
- Distributed Denial-of-Service (DDoS) attacks
- Automated bot traffic
- Common web application attacks
- Malicious IP addresses and suspicious network behaviour
- Traffic anomalies and abuse
Security rules and threat detection capabilities are continuously reviewed and refined to respond to the evolving cybersecurity landscape.
Application Security & Identity Protection
Security is integrated throughout the platform lifecycle to protect user accounts, application services, and sensitive information.
Our security measures include:
- Secure authentication and session management
- Mobile number verification using one-time password (OTP) authentication
- Email verification during account registration
- Optional secure third-party authentication where available
- Password protection using industry-standard cryptographic practices
- Encrypted communications using Transport Layer Security (TLS)
- Secure development and deployment practices
- Regular software updates and vulnerability remediation
We continuously review authentication and access controls to help prevent unauthorized access to user accounts.
Data Protection & Privacy
Protecting personal information is fundamental to our platform.
We apply appropriate technical and organizational safeguards designed to protect personal data throughout its lifecycle.
These safeguards include:
- Encryption of data during transmission
- Secure storage of personal information
- Access controls based on business need
- Authentication and authorization controls
- Audit logging where appropriate
- Data minimization principles
- Secure deletion processes where applicable
Personal data is processed in accordance with our Privacy Policy, applicable contractual obligations, and relevant data protection legislation.
Monitoring & Incident Response
We continuously monitor platform activity to help identify, investigate, and respond to potential security events.
Our operational security practices include:
- Continuous monitoring of system performance
- Detection of unusual or suspicious activity
- Security event logging
- Vulnerability assessments
- Regular software maintenance
- Prompt deployment of security updates
- Incident investigation and remediation procedures
Where appropriate, we work with trusted technology providers and security partners to support the reliability and resilience of our services.
Responsible AI & Information Integrity
JobsForNationals uses artificial intelligence technologies to enhance certain platform services, including AI-powered job previews, content generation, user engagement, and other productivity features.
AI technologies are intended to support users and improve platform functionality rather than replace human judgement.
Where appropriate:
- AI-generated content is reviewed before publication.
- Human oversight is maintained for business-critical decisions.
- AI outputs may be refined, edited, or validated prior to use.
- Employers remain solely responsible for their recruitment and hiring decisions.
We continuously monitor developments in AI governance, privacy, transparency, and information integrity to ensure the responsible use of emerging technologies.
Security Governance & Compliance
JobsForNationals continuously reviews and enhances its security controls to align with recognised industry standards and evolving regulatory requirements.
Our security programme is informed by internationally recognised best practices, including principles reflected in:
- ISO/IEC 27001 – Information Security Management
- ISO/IEC 27018 – Protection of Personal Data in Cloud Environments
- ISO/IEC 27701 – Privacy Information Management
- SOC 2 Security Principles
- UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)
Where third-party service providers are engaged to support platform operations, we require them to implement appropriate contractual, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of personal information.
Security Awareness & Continuous Improvement
Cybersecurity is an ongoing process rather than a one-time implementation.
We regularly review and improve our security practices by:
- Monitoring emerging cybersecurity threats
- Reviewing security controls and operational procedures
- Applying software and infrastructure updates
- Assessing new technologies and security enhancements
- Periodically reviewing access permissions
- Evaluating regulatory developments affecting privacy and security
- Continuously improving operational resilience
This continuous improvement approach helps ensure that our security practices evolve alongside technological advances and emerging cyber risks.
Security Incident Management
In the event of a suspected security incident, JobsForNationals follows established internal procedures to assess, investigate, contain, and remediate the issue as quickly as reasonably practicable.
Where required by applicable law, affected users and relevant regulatory authorities will be notified in accordance with applicable legal obligations.
Following any significant security event, we review our controls and processes to reduce the likelihood of similar incidents occurring in the future.
Third-Party Service Providers
JobsForNationals works with carefully selected third-party service providers that support the operation of the Platform, including infrastructure, communications, authentication, analytics, payment processing, and security services.
Where personal data is processed by third-party providers:
- appropriate contractual safeguards are implemented;
- providers are expected to maintain appropriate security standards;
- providers remain responsible for complying with applicable data protection laws relating to the services they perform.
Our use of third-party providers does not diminish our commitment to protecting the personal information entrusted to us.
Contact
For inquiries related to our cloud security practices:
Email: [email protected]
Subject: Cloud Security Inquiry
We believe that trust is built through transparency and proactive protection. Our users can be confident that their data is handled with the highest level of care and security.